
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-15172 is a denial-of-service vulnerability in the FMP/NOTIFY protocol dissector of Wireshark, caused by improper handling of loop conditions when parsing malicious network capture files. It affects Wireshark versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16. The vulnerability was published on July 8, 2026, with patches available in versions 4.6.7 and 4.4.17. It carries a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory, Red Hat Bugzilla).
The root cause is classified under CWE-606 (Unchecked Input for Loop Condition) and CWE-1286 (Improper Validation of Syntactic Correctness of Input), meaning the FMP/NOTIFY dissector fails to properly validate packet data used to control loop execution, potentially resulting in an infinite loop. Exploitation requires a local attacker to craft a malicious pcap file and have a user open it in Wireshark or TShark; the attack vector is local with no privileges required but user interaction is necessary. A proof-of-concept was published on the Wireshark GitLab issue tracker, including specific malicious pcap files (dos.pcap, overflow.pcap) and a PowerShell command to trigger the infinite loop DoS (Wireshark GitLab, GitHub Advisory).
Successful exploitation causes Wireshark or TShark to crash or enter an infinite loop, resulting in a complete loss of availability for the application. There is no impact on confidentiality or data integrity, as the vulnerability is limited to a denial-of-service condition. The scope is confined to the affected Wireshark process and does not enable lateral movement or data exfiltration (GitHub Advisory, Red Hat Bugzilla).
dos.pcap) containing a malformed FMP/NOTIFY protocol packet designed to trigger an unchecked loop condition in the dissector.Start-Process "C:\Program Files\Wireshark\tshark.exe" "-r dos.pcap" on Windows.dos.pcap, overflow.pcap) in user download directories or shared network locations.wireshark.exe or tshark.exe shortly after opening a specific capture file.Update Wireshark to version 4.4.17 or 4.6.7 (or later) to remediate the vulnerability (Wireshark Security, GitHub Advisory). As a workaround until patching is complete, restrict untrusted users from opening capture files in Wireshark and avoid opening pcap files from untrusted or unknown sources. Fedora and other Linux distributions have also issued updated packages addressing this vulnerability.
Red Hat tracked the issue via Bugzilla (Bug 2498306) and assigned it medium severity, with the bug filed by the OSIDB automated import system (Red Hat Bugzilla). Fedora issued updated Wireshark packages addressing this and related vulnerabilities, with coverage noted on Linux security news sites. No significant independent researcher commentary or broad social media discussion has been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."